用友NC 电采warningDetailInfo SQL注入漏洞

2024-06-20 用友NC PoC No

Description

NC系统可以利用/ebvp/infopub/warningDetailInfo接口的 pkMessage参数,实现sql注入,从而窃取服务器信息。

影响版本:

NC63、NC633、NC65

PoC

None yet. Search at https://trap.biu.life/?ref=rss

References

Related Vulnerabilities